diff --git a/.github/workflows/scorecard.yml b/.github/workflows/scorecard.yml
index d9e845ce02804b80013219c7e1d1e1a4a16132a2..022ca883376485be47e8f005184a6da9d25f5c3e 100644
--- a/.github/workflows/scorecard.yml
+++ b/.github/workflows/scorecard.yml
@@ -25,7 +25,7 @@ jobs:
           persist-credentials: false
 
       - name: 'Run analysis'
-        uses: ossf/scorecard-action@e38b1902ae4f44df626f11ba0734b14fb91f8f86 # v2.1.2
+        uses: ossf/scorecard-action@08b4669551908b1024bb425080c797723083c031 # v2.2.0
         with:
           results_file: results.sarif
           results_format: sarif